Candidate: CVE-2015-4645 PublicDate: 2017-03-17 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4645 http://www.openwall.com/lists/oss-security/2015/06/18/10 Description: Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow. Ubuntu-Description: Notes: amurray> xenial got updated to 1:4.3-3ubuntu2.16.04.3 fixing this (LP: #1785499) Bugs: https://bugs.launchpad.net/bugs/1785499 Priority: low Discovered-by: Giancarlo Canales Barreto Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_squashfs-tools: upstream_squashfs-tools: released (1:4.3-2) precise_squashfs-tools: ignored (reached end-of-life) precise/esm_squashfs-tools: DNE (precise was needed) trusty_squashfs-tools: ignored (reached end-of-life) trusty/esm_squashfs-tools: DNE (trusty was needed) utopic_squashfs-tools: ignored (reached end-of-life) vivid_squashfs-tools: ignored (reached end-of-life) vivid/stable-phone-overlay_squashfs-tools: DNE vivid/ubuntu-core_squashfs-tools: ignored (reached end-of-life) wily_squashfs-tools: ignored (reached end-of-life) xenial_squashfs-tools: not-affected (1:4.3-3) esm-infra/xenial_squashfs-tools: not-affected (1:4.3-3) yakkety_squashfs-tools: ignored (reached end-of-life) zesty_squashfs-tools: ignored (reached end-of-life) artful_squashfs-tools: ignored (reached end-of-life) bionic_squashfs-tools: not-affected (1:4.3-3) cosmic_squashfs-tools: not-affected (1:4.3-3) disco_squashfs-tools: not-affected (1:4.3-3) devel_squashfs-tools: not-affected (1:4.3-3)